- Category: backdoor Trojan, network aware worm.
- Process name: cndrive32.exe.
- File location: %systemroot%\cndrive32.exe.
- Size: 339,968 bytes.
- Registry Activity: *[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] > Microsoft Driver Setup = "%Windir%\cndrive32.exe". *[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] > Microsoft Driver Setup = "%Windir%\cndrive32.exe".
- Run, and type "gpedit.msc". Go to User Configuration > Administrative Templates > System and double click Don’t run specified Windows applications.
- Set to Enabled, click Show button next to List of disallowed applications. Click Add button and enter the name (cndrive32.exe).
cndrive32.exe by thecybergal
- If there are other programs that you suspect, just enter the name of the program such as the steps above.
Adapted from the letter of:
- Ahmad Syahruddin (asm2000@yahoo.com)
- Motta Gare (mottagare@yahoo.com)
nice info..keep posting, kawan........
ReplyDeleteBonne nuit mon ami. Je m'excuse auprès de visite en utilisant la langue française. Je veux des amis avec vous.
ReplyDeletemampir coyy, thanks infonya
ReplyDeleteGOOD TIPS,
ReplyDeletethanks...